CVE-2022-21194

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
11/03/2022
Last modified:
18/03/2022

Description

The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:* r5.01.00 (including) r5.04.20 (including)
cpe:2.3:o:yokogawa:centum_vp_firmware:*:*:*:*:*:*:*:* r6.01.00 (including) r6.09.00 (excluding)
cpe:2.3:h:yokogawa:centum_vp:-:*:*:*:*:*:*:*
cpe:2.3:o:yokogawa:centum_vp_entry_firmware:*:*:*:*:*:*:*:* r4.01.00 (including) r4.03.00 (including)
cpe:2.3:o:yokogawa:centum_vp_entry_firmware:*:*:*:*:*:*:*:* r5.01.00 (including) r5.04.20 (including)
cpe:2.3:o:yokogawa:centum_vp_entry_firmware:*:*:*:*:*:*:*:* r6.01.00 (including) r6.09.00 (excluding)
cpe:2.3:h:yokogawa:centum_vp_entry:-:*:*:*:*:*:*:*
cpe:2.3:a:yokogawa:exaopc:*:*:*:*:*:*:*:* r3.72.00 (including) r3.80.00 (excluding)


References to Advisories, Solutions, and Tools